mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-09 00:40:45 +08:00
重构仓库目录为统一的 runtime 分层并清理历史 openclaw 残留。
本次迁移将网关/通道/工具/技能/脚本与协议资源集中到新结构,统一路径常量与脚本转发机制,减少顶层噪音并保证运行与测试行为一致。 Made-with: Cursor
This commit is contained in:
parent
ba3836f00f
commit
4a23b715a2
498 changed files with 2760 additions and 2200 deletions
53
tests/test_oclaw_relay_pointer_security.py
Normal file
53
tests/test_oclaw_relay_pointer_security.py
Normal file
|
|
@ -0,0 +1,53 @@
|
|||
from __future__ import annotations
|
||||
|
||||
import base64
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
from oclaw.runtime.relay_pointer import (
|
||||
RelayPointerError,
|
||||
build_pointer_uri,
|
||||
decode_base64_payload,
|
||||
normalize_rel_path,
|
||||
parse_pointer_uri,
|
||||
safe_join_under_root,
|
||||
sha256_hex,
|
||||
validate_file_name,
|
||||
)
|
||||
|
||||
|
||||
def test_validate_file_name_rejects_path_injection() -> None:
|
||||
with pytest.raises(RelayPointerError):
|
||||
validate_file_name("../a.txt")
|
||||
with pytest.raises(RelayPointerError):
|
||||
validate_file_name("a/b.txt")
|
||||
|
||||
|
||||
def test_normalize_rel_path_rejects_traversal() -> None:
|
||||
with pytest.raises(RelayPointerError):
|
||||
normalize_rel_path("../../etc/passwd")
|
||||
|
||||
|
||||
def test_safe_join_under_root_stays_inside(tmp_path: Path) -> None:
|
||||
p = safe_join_under_root(tmp_path, "a/b.txt")
|
||||
assert str(p).startswith(str(tmp_path.resolve()))
|
||||
|
||||
|
||||
def test_decode_base64_payload_respects_size_limit() -> None:
|
||||
raw = base64.b64encode(b"hello").decode("ascii")
|
||||
assert decode_base64_payload(raw, max_bytes=5) == b"hello"
|
||||
with pytest.raises(RelayPointerError):
|
||||
decode_base64_payload(raw, max_bytes=4)
|
||||
|
||||
|
||||
def test_pointer_uri_build_and_parse_roundtrip() -> None:
|
||||
uri = build_pointer_uri("scope_1", "abcdef123456")
|
||||
assert uri == "relay://attachments/scope_1/abcdef123456"
|
||||
scope, file_id = parse_pointer_uri(uri)
|
||||
assert scope == "scope_1"
|
||||
assert file_id == "abcdef123456"
|
||||
|
||||
|
||||
def test_sha256_hex_is_stable() -> None:
|
||||
assert sha256_hex(b"abc") == "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
|
||||
Loading…
Add table
Add a link
Reference in a new issue